Network Device
Review
Configuration hardening review of routers, switches, and firewalls against best security practices including CIS benchmarks and vendor security guides, for Cisco IOS/NX-OS, Palo Alto PAN-OS, Fortinet FortiOS, Juniper JunOS and more...
Network devices sit at the choke points of your infrastructure, but their configurations are often set once at deployment and rarely revisited. Overly permissive firewall rules, weak management-plane authentication, and unauthenticated routing protocols persist for years.
Our network device reviews assess routers, switches, and firewalls against CIS benchmarks and vendor-specific hardening guides for Cisco IOS/NX-OS, Palo Alto PAN-OS, Fortinet FortiOS, and Juniper JunOS — covering management-plane hardening, control-plane protections, and firewall rulebase hygiene.
Rulebases receive manual review alongside automated checks: shadowed rules, unused objects, and "any-any" entries are exactly the kind of thing benchmark scanning alone will miss.
Scope & Baseline Selection
Confirmation of device models, OS/firmware versions, and role — edge firewall, core switch, VPN gateway — to identify applicable practices and benchmarks.
Configuration Extraction
Secure export of running configuration, ACLs, firewall rulebases, and routing tables via SSH, console, or provided configuration backups. No changes made to live devices.
Automated benchmark Analysis
Comparison against CIS and vendor benchmarks across management-plane hardening (AAA, SSH, SNMP), control-plane protections, and logging/monitoring configuration.
Manual Rulebase & ACL Review
Manual review of firewall rulebases and ACLs for overly permissive "any-any" rules, unused or shadowed rules, weak NAT configuration, and unauthenticated routing protocol peering.
Risk Prioritisation
Findings ranked by potential for network segmentation bypass, management-plane compromise, or traffic interception — ordered by exploitability and blast radius.
Remediation Guidance & Delivery
Vendor-specific remediation configuration snippets and a prioritised fix list, delivered in a format ready for your change-control process.
We review rulebases manually as well as against benchmarks — shadowed and overly permissive rules are the findings that matter most and the ones automated scanning consistently misses.